In the small but influential world of those investing in - or betting on - AI, there are different models of how it can and should develop: In the US, the hyperscalers are at the top, with huge returns to scale; in Europe, those hyperscalers are seen as invaders trying to sneak in from the side, but without much understanding of or respect for the local markets, their norms, and their laws. Likewise, the notion of sovereign AI - to counterbalance the growing power of hyperscalers - has different meanings. In the US, it’s mostly an open-source, power-to-the-people, technical thing. In Europe, it’s more a “power to our own country and culture” notion. In both worlds, while security is mostly seen as costly friction, it can also provide a moat - or a business opportunity.
In the US, there is business concentration and the intertwining of power and money at the top - i.e. monopolies, government favors and the like - and lack of agency at the bottom. Indeed, the US government and its AI leaders are - and are considered to be - joined in a quest for global domination. (Meanwhile, I would argue that China’s celebration of open source is good PR for a non-open government.)
What are the alternatives? In Europe, individual companies and governments are more like allies trying to assert local control in a more horizontal structure. A few of the smart people I met are thinking more deeply about decentralization and localization, for financial, technical, and political reasons.
Last week, I met with two start-ups paying attention to specific slots in this hierarchy. The first is Teravolt, basically a picks-and-shovels company focused on building out physical infrastructure, not fighting the LLM wars but making sure the players are well provisioned, and going after not the biggest market but the least served one. The second is Antefact, with a solo founder (for now), going after the software equivalent of the resilience/maintenance market (h/t Stewart Brand): Security/quality assurance that learns and improves from experience in real time, rather than simply applying rigid guardrails that are vulnerable to erosion from outside actors or new use cases. Interestingly, both of them, though they are based in the UK, were founded by people from other countries.
Teravolt operates out of London; its founders’ family stories run from Russia to Greece by way of Turkey and Armenia - which may explain their comfort operating across regions most investors fly over. (For those who don’t know - including me until now - Teravolt is a reference to certain superpowers in Pokémon. TLDR, but you can ask your favorite chatbot.) They are betting on a long game: that the value of local AI compute capacity will increase even as the valuation of large-scale US data centers will be eroded by competition and commoditization over time. The company is building the physical layer for decentralized inference: a grid of regional facilities that serve models close to where users, data and regulators actually are, much as content delivery networks once moved content closer to eyeballs. Their method is brownfield: Instead of managing multi-year greenfield builds, Teravolt converts existing industrial sites - old factories, former crypto-mining facilities, land near power plants and battery energy storage system projects - where the grid connection, the substation, and often the permits already exist. That compresses time-to-power from years to months. Some of the workloads on these facilities will be small language models (SLMs); many will be private or sovereign deployments of LLMs (call them “customized” LLMs?). Either way, their value comes not from scale but from customization for specific markets, governance regimes, and data.

To US investor eyes, Teravolt is not at the head of the beauty parade: The map above shows its current market targets. But the founders, Denis Alkhazov and Laert Karaashev, have a plan - and not a lot of likely competition. They understand how slowly the real world of physical infrastructure and human bureaucracy moves, and figure that acting now is a forward investment in processing capacity that cannot be built overnight because it needs existing facilities, buildings, communications infrastructure, and most of all, permissions from local communities. (Perhaps that is also more true in the US than the hyperscalers have recognized.)
Here is how Teravolt describes itself (lightly edited). It’s worth reading slowly; it’s not generic.
The thesis in one paragraph: The compute infrastructure of intelligence is crystallizing into a four-tier planetary hierarchy [no Dyson spheres yet, I guess!]: gigafactories manufacture intelligence where the electron is cheap [tier 3]; regional hubs balance energy, backbone fiber, and sovereignty [tier 2]; hyperlocal urban nodes [tier 1] sell the millisecond latency, the jurisdiction, and the memory; devices [tier 0 - end-users] keep the reflexes. By 2036 this hierarchy will add up to roughly 3,500-6,000 facilities worldwide - and its value is distributed against current intuition: the watts sit at the top, but pricing power grows downward, because irreplaceability of location grows downward. By the early 2030s everything in this industry will be commoditized - capital, chips, construction, energy - except one layer: the ability to assemble, on the ground, the right to a megawatt built upon grid connection queues, land near the substation, permits, and local trust. That layer takes years and local know-how to assemble; capital can buy its product at a generous premium, but cannot acquire the layer itself. History suggests how this ends: The neutral holders of irreplaceable points - cell towers, internet exchanges, airports - have consistently ended up worth more than their tenants. The layer is made of time - and for now, the market still prices those years as land and paperwork, not as the premium they will earn.
I would add that at the top, tier 3 (the gigafactories), you have the LLMs and the scalable training. At tier 2 (regional hubs) you have the inference and less compute-intensive affordances: local training; small language models; unique and often proprietary data sets, whether corporate or government data; and most importantly, security, situation- and organization-specific rules, and the like. Below that, at tier 1, you find mostly business users of the compute and semi-standard autonomous AIs. Finally, at what Teravolt calls tier 0, you find software on personal devices used mostly by individuals. But all these tiers interact, and functions shift across them, just as a human body is not a set of body parts but an intricately connected system with both a central brain and a decentralized immune system - plus a foreign microbiome.
Teravolt’s premise is that the market is paying too much attention to the hyperscalers and missing the need for local capacity - both physical infrastructure and the local data and models that will live in it. They also see that this market is slower to grow - and the infrastructure underneath is even slower to build and repair…so that their value will be in providing that infrastructure on time by starting now. They see this market as ultimately both larger and more profitable than the huge but commoditizing giant data center market currently bubbling along in the US. In Europe in particular, decentralized infrastructure can support precisely the decentralized autonomy that the governments and the people themselves value. More broadly, Teravolt’s locations are not exotic picks for their own sake. Southeast Europe, Central Asia, and Caucasus have what saturated markets ration: available power, existing industrial sites, and governments that can still say yes in months. And they sit exactly where regional and sovereign inference will need a local home.
Does it do what it says on the tin?
What kind of sovereignty and security will ultimately deliver the potential value of all this infrastructure and the autonomous/agentic AI it will support? That depends on proper limits to agency and ultimately on accountability: How can we make sure that autonomous AI actually - as they say in the UK - does what it says on the tin?
One big issue is security in all its aspects. The LLM builders are beginning to take this seriously, as is the conflicted government that wants to impose worldwide sovereignty over them (that’s the US, if you are reading this too quickly). Just as makers of machines learned the need for maintenance against wear and tear, the makers of AI will be learning about the need for something similar to protect against a different kind of fragility - susceptibility to attacks and the need to keep updating security.
That security will work differently depending on the nature of the AI. The security needed by LLMs is more generalizable and at a different level from that of the autonomous/agentic systems many of them run or interact with. LLMs are expensive to train; that investment is then realized through the broad use of those LLMs, which gets increasingly profitable at scale. The LLMs themselves are unpredictable and sycophantic; they chat and follow instructions - and give advice of variable quality. But they are not themselves autonomous agents, which often use LLMs to create code or to interact and negotiate with other systems. Those more specific SLMs and other targeted autonomous systems are more complicated and expensive to train for specific uses, and to restrain from specific mistakes. That training happens mostly at tiers 3 and especially 2. (At tiers 1 and 0 it’s mostly people using or interacting with agents, and they create their own security risks.)
Ultimately, I believe the greatest short-term and less visible dangers (vs. the creation of dangerous viruses, predatory drones and the like) lie with autonomous software that acts outside its owner’s organization. Autonomous software operating within a company or government has fairly clear owners and accountability. But once it starts interacting with or being sold to third parties for their own use, security and quality assurance get more complicated, because here it’s dealing with more specifics, and with outside entities that may not share its goals. What’s the ability of that other party to misuse the software, whether on purpose or by mistake? What kinds of actions are permissible, and what others are dangerous? For example, these can range from criteria for firing someone in an HR framework, to a transaction that looks normal but that quietly represents coercion or a bribe delivered somewhere else. How well does the whole system “understand” what’s going on in all the different entities it interacts with?
While training an LLM to ensure its security is complicated and expensive and requires great scale, building autonomous software is less so - but each instance of this software has a much smaller, more targeted user/customer base (and smaller economies of scale). Most autonomous/agentic AIs just use the great power of an LLM in a limited context, around certain functions, interacting with a variety of other systems to perform a limited number of tasks. But the trade-offs and choices of deciding what specific data and capabilities it should have access to, and controlling that access using specific data and roles and other criteria, are also a business opportunity. For example, while healthcare data is controlled by HIPAA and financial data is controlled by a fairly complex set of banking rules, the vulnerabilities for other fields are often similarly complex but less defined. That’s precisely where things get interesting, because both in real life and in software you ultimately have to balance risk with getting the job done. The real world is messy. Can you let the intern talk to a client? Probably yes. Can you have them file a legal brief? Probably not.
Dealing with that messiness is the mission of Antefact, an early-stage startup founded by Zack Dadfar, the son of an Iranian who immigrated to the UK during the Iranian revolution. Based in the city of Manchester, he has made some fairly groundbreaking but nerdy discoveries about how models managing autonomous AI can show signals that their joint work may be unreliable, before they even finish performing it. (This reminds me of the difference between product manuals and “performance support,” where software watches user behavior and intervenes in real time as necessary.) In some way that he is hoping to patent, Dadfar’s security/quality assurance tool can discern how hard an autonomous AI is struggling to make its decisions. How much, in essence, does the system show signs of not trusting its own work? How likely is this output to result in failure?
Antefact’s software uses this approach to enhance the reliability and security of autonomous AIs for its customers, who are running their own systems (whether built in-house or purchased from a vendor). Ensuring the proper operation of an autonomous AI is about as challenging a task as trying to control autonomous humans, but in different ways. As with humans, the earlier in the process one intervenes, the easier…but of course one has to be primed to notice. Antefact’s software intervenes as early as possible - during inference, before the system is trusted or allowed to act.
This intervention allows/forces the AI system and its users to focus their attention on the tough cases, using the AI’s own reactions to the work it’s doing as a signal of risk. Imagine walking through your office: Are you going to chat with everyone, or zero in on the intern pulling her hair out in the corner? That focus is what Antefact causes.
The next question, of course, is what to do once you know where to focus. Antefact and other tools can start by quantifying the risk, but what can the builder do to reduce it? First, of course, stop the process, but then it’s time to figure out what the danger might be, what a better answer might be, what constraints to apply. Antefact’s first use cases are medical, such as detecting when a medical AI system is at risk of giving the wrong diagnosis.
But the approach - and the specific algorithms - can work across sectors. Says Dadfar: “Antefact is the runtime reliability layer for AI. It detects early signs of failure from inside a model while it is still working, and turns those signals into controls that decide whether an inference should continue, be checked, retried, rerouted or stopped. Because Antefact can intervene before a full answer is produced, it can reduce wasted tokens, latency and downstream verification costs while focusing attention on the cases that actually need them. It sits upstream of today’s guardrails, evaluators and review systems - not replacing them, but making them more selective, faster and more efficient.” And it learns from its own successes and failures. Dadfar wrote the original software and designed it to train itself further on the job. But he is also still tweaking it himself. And presumably, eventually he’ll be hiring other coders as the market - and the risks - evolve.
I like to think of this whole process as the software version of resilience or anti-fragility (h/t Nicholas Nassim Taleb), vs. repair. The system’s - and its human builders’ - reactions to challenges prompt them to become more secure and more resilient. It’s not a process that ever ends. And so the sooner you begin, the longer you may prosper.
What does this all mean?
There’s no simple conclusion to draw from these two examples, and no easy way to predict where the world as a whole goes from here. Both these companies have interesting and credible approaches to market structures that differ from those in the US, where the big players are already using their strength to stake out multiple major market sectors. Anthropic and Open AI are both making moves in healthcare, while Google continues to reorganize its healthcare operations and establish a variety of healthcare partnerships. And one way or another, all the big players seem to be eyeing legal and finance as appealing extensions of their huge underlying compute capacity.
In the end, maybe the whole notion of hierarchy needs to shift. The world is less a stack than a ball. The dependencies between any person or entity with agency inevitably are two-way, even though they are rarely fully balanced. “Sovereignty” still sounds like a land grab more than a negotiation. The potential value of AI is not to squash people into quantifiable vectors, but rather to bring their unique voices and needs into the mix in a way that reflects their complexity rather than their average distribution.
This is a sitrep, not a conclusion. Please stand by.

Great read! What an experience you had!